yutori-computer-use

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities largely align, and the Yutori package path appears official, but it grants very powerful desktop permissions, forwards a stored API key to CLI tooling, and relies on a separate third-party driver for core functionality. This looks like a legitimate but high-impact computer-use skill with notable supply-chain and autonomy risk rather than confirmed malware.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Sep 1, 2026, 10:29 PM
Package URL
pkg:socket/skills-sh/yutori-ai%2Fyutori-mcp%2Fyutori-computer-use%2F@7d57df49ade1182d23d7b2cfe7e5e4dc9db7154dacc431bfacda6c37746edccd
Security Audit — socket — yutori-computer-use